VORANT. Threat Intelligence Sign in Get the full feed

URLhaus adds DNS RPZ feed for malware blocking

low threat

abuse.ch released a DNS Response Policy Zone feed from URLhaus data to block malware distribution domains, updated every 5 minutes and excluding Alexa Top 1M sites.

abuse.ch has introduced a DNS Response Policy Zone (RPZ) feed derived from URLhaus, which has tracked over 200,000 malware URLs. The RPZ feed enables system administrators to block DNS resolution for domains actively distributing malware by returning NXDOMAIN responses. The feed updates every 5 minutes and excludes Alexa Top 1M sites to minimize false positives.

The primary threats tracked by URLhaus include Emotet (Heodo), Mirai, Gayfgyt, and Gozi ISFB (Ursnif). The RPZ implementation is compatible with DNS servers supporting the RPZ standard, including Bind and PowerDNS. The blog post provides detailed configuration instructions for Bind on Ubuntu 18.04.2 LTS, including setup of automated updates via cron and optional logging of blocked queries.

This defensive capability allows organizations to leverage community-sourced threat intelligence to prevent users from accessing known malware distribution infrastructure at the DNS layer, providing an additional control point for network security.

Mentioned in this report

Malware EmotetGayfgytGozi ISFBHeodoMiraiUrsnif

Source reporting: https://abuse.ch/blog/using-urlhaus-as-response-policy-zone-rpz

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free